A company is using Amazon CloudFront to distribute static content from an S3 bucket. The content is updated frequently, but users see stale content. The developer wants to ensure that new content is served as soon as possible after an update. Which action should be taken?
Creating a CloudFront invalidation request specifically targets and removes specified objects from all CloudFront edge caches globally. Upon successful invalidation, the next request for those objects at any edge location will result in CloudFront fetching the latest version directly from the origin. This is the most direct and effective method to ensure users immediately receive updated content after changes have been deployed to the origin, overriding any existing TTL settings.
Why this answer
CloudFront caches content at edge locations based on TTL settings. When content is updated in the S3 origin, existing cached copies remain stale until they expire or are explicitly invalidated. Creating a CloudFront invalidation for the updated files immediately removes the cached objects from all edge locations, forcing CloudFront to fetch the latest version from S3 on the next request.
This ensures new content is served as soon as possible after an update.
Exam trap
The trap here is that candidates confuse TTL configuration (which controls how long new objects are cached) with invalidation (which removes already-cached objects), leading them to pick options that only affect future caching behavior without addressing the stale content already served.
How to eliminate wrong answers
Option A is wrong because enabling Origin Shield reduces the number of requests to the S3 origin by consolidating them at a regional cache layer, but it does not force CloudFront to serve fresh content; it can actually increase staleness by adding another caching layer. Option B is wrong because setting Minimum TTL and Default TTL to 0 tells CloudFront to respect the Cache-Control max-age=0 header from the origin, but if the S3 object does not have that header (or has a higher max-age), CloudFront will still cache the content for the origin's specified duration; TTL settings alone do not purge already-cached content. Option C is wrong because 'Object Caching' is not a configurable numeric field in CloudFront; the correct setting is 'Minimum TTL', 'Maximum TTL', and 'Default TTL' under the 'Cache Based on Selected Request Headers' behavior, and setting these to 0 does not invalidate existing cached objects.